Impact
The Admin Custom Login plugin allows an authenticated attacker with administrator permissions to place arbitrary scripts in the "Message Above Login Form" setting. These scripts are stored and executed every time a user visits a page that includes the setting, providing the attacker with a persistent cross‑site scripting vector that can be used for defacement, session hijacking, or other malicious actions performed in the context of the victim’s browser.
Affected Systems
The vulnerability exists in weblizar’s Admin Custom Login plugin for WordPress, affecting all releases up to and including version 3.6.4. It is only exploitable on multi‑site WordPress installations where the unfiltered_html option has been disabled and where users with administrator‑level roles can modify the "Message Above Login Form" setting.
Risk and Exploitability
With a CVSS score of 4.4 the issue is considered low severity. No EPSS score is available, and the vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is local: an attacker must first gain administrator access to modify the plugin setting. Once the script is stored, any user who views the affected page will be exposed to the injected code. The overall risk depends largely on the presence of trusted administrators and the configuration of the mult-site setup.
OpenCVE Enrichment